Improper access control in Unbound - CVE-2026-55708
Published: July 23, 2026
Unbound
Detailed vulnerability description
The vulnerability allows a remote user to bypass local DNS policy protections.
The vulnerability exists due to improper access control in the unbound-control view_local_data and view_local_datas command handling when creating local zones for an already configured named view with no local data. A remote user can invoke the control interface to bypass local DNS policy protections.
Queries for default-protected names from clients mapped to the affected view may be forwarded to the public DNS instead of being answered locally.